Privacy and Cookie Policyyyyy
This privacy policy describes the processing of personal data when using the Clever Dialer Android app. It also explains the choices you have regarding your personal data (“Your rights”) and how you can contact us.
Note on the language version: This document is a translation of the German original. The German version is authoritative; in the event of any discrepancy or ambiguity in the translation, the German wording shall be used for interpretation. This does not affect your statutory rights. The German version is available at www.cleverdialer.app/datenschutzerklaerung-android-app.
I. Controller and Data Protection Officer
1.1 The controller within the meaning of the GDPR is:
Sellwerk GmbH & Co. KG
Pretzfelder Straße 7–11
90425 Nuremberg
Email: support@cleverdialer.de
Commercial Register Nuremberg HRA 16002
Managing Directors: Dipl. Kff. Constanze Oschmann, Dipl. Kfm. Michael Oschmann
For questions regarding the processing of your personal data, please contact our Data Protection Officer, Dr Stefan Drewes, who can be reached at the address stated in the Legal Notice or at: privacy@cleverdialer.com
II. Your rights as a data subject
2.1 Every data subject has the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification of inaccurate data (Art. 16 GDPR)
- Right to erasure, or a right to be “forgotten” (Art. 17 GDPR)
- Right to restriction of the processing of personal data (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
You may object at any time, without giving reasons, to the processing of personal data for advertising purposes, including an analysis of customer data for advertising purposes.
In addition, the data subject also has a general right to object (cf. Art. 21(1) GDPR). In that case, the objection to a data processing operation must be substantiated. Where the data processing is carried out on the basis of consent, your consent may be withdrawn at any time with effect for the future.
To exercise your data subject rights, the easiest way is to contact support@cleverdialer.de or the address stated in the Legal Notice. In addition, you have the right to lodge a complaint with the data protection supervisory authority responsible for you.
III. Processing of personal data by Sellwerk GmbH & Co. KG
1 Incoming calls
Clever Dialer identifies incoming calls and, where applicable, warns of spam phone calls. To provide this service, the Clever Dialer Android app first determines the phone number of the incoming call. This phone number is then transmitted to the Clever Dialer web service. There, all available sources (Das Örtliche, Das Telefonbuch, Gelbe Seiten) as well as the Clever Dialer spam database are searched for information on this number. Any information found is then displayed to the user. Spam warnings are shown for both incoming and outgoing calls.
So that spam information is also available when there is no data connection at the time of an incoming call, a list of spam numbers is stored on the device. This list is updated several times a day. For caller identification itself, a request to the Clever Dialer web service is required, as this data cannot be held locally.
At various points in the app, the user can submit ratings on a phone number or a call. These ratings are stored by Clever Dialer and made available to other users. A further signal that is stored is how many users have blocked a particular phone number.
The rating of a spam number is calculated from various signals. Clever Dialer does not store individual call events. Only aggregated statistical information at phone number level is stored, and only for numbers classified as spam or blocked by users. Specifically, this concerns the following data:
- Phone number (only for numbers classified as spam or blocked)
- Total number of calls to this number
- Number of calls to this number classified as spam
- Number of blocked calls to this number
- The country in which the call was received
This data is not assigned to a particular user or device; no user or device identifier is stored. As no individual call events are stored, there is likewise no time-based deletion of individual call records. The statistical data on a phone number is retained for as long as the number is listed in the Clever Dialer spam database and is deleted as soon as the number is removed from the database.
To identify incoming calls, the caller’s phone number is transmitted via our web service to public telephone directories (Das Örtliche, Das Telefonbuch, Gelbe Seiten). These services receive only the queried phone number; they cannot assign it to the app user. Owner data is resolved via public telephone directories exclusively for German phone numbers (country code +49). For phone numbers from other countries, only spam detection based on the Clever Dialer spam database takes place; owner data is not queried.
The legal basis for this processing is Art. 6(1)(b) GDPR. The transmission of the phone number and the comparison with directory databases are necessary to perform the usage contract — specifically, to provide the caller identification and spam protection function.
2 Outgoing calls
Clever Dialer identifies outgoing calls and, where applicable, warns of spam phone calls. For this purpose, the Clever Dialer Android app determines the phone number of the outgoing call and transmits it to the Clever Dialer web service. There, the phone number is compared with the available directory databases (Das Örtliche, Das Telefonbuch, Gelbe Seiten) as well as the Clever Dialer spam database. The results — including any spam warnings — are displayed to the user.
Storage: The transmitted phone number is processed on the server solely to carry out the comparison and is not stored thereafter. Phone numbers of outgoing calls are not stored permanently.
To identify outgoing calls, the phone number is transmitted via our web service to public telephone directories (Das Örtliche, Das Telefonbuch, Gelbe Seiten). These services receive only the queried phone number; it cannot be assigned to the app user. Owner data is resolved via public telephone directories exclusively for German phone numbers (country code +49). For phone numbers from other countries, only spam detection based on the Clever Dialer spam database takes place; owner data is not queried.
Legal basis: Art. 6(1)(b) GDPR. The transmission and the comparison are necessary to provide the contractually agreed caller identification and spam protection function.
3. Information for number holders (callers and rated phone numbers)
Clever Dialer identifies incoming calls and helps users protect themselves against spam and fraud. In doing so, data of persons who are not themselves users of Clever Dialer is also processed — in particular holders of phone numbers that are stored in our database or queried in the course of an incoming call.
Which data do we process?
- Phone number
- Where applicable, name or company name, insofar as apparent from public sources
- Number type (landline, mobile) and country or area code assignment
- Spam rating
- Category of the call (e.g. “advertising call”, “suspected fraud”), which is derived automatically from the comments of our users
- Where applicable, ratings and comments from our community on this number
Where does this data come from?
- Publicly accessible telephone directories (Das Telefonbuch, Das Örtliche, Gelbe Seiten)
- Ratings and spam reports from our user community
- For incoming calls: the phone number transmitted by the telecommunications network to the called party
Why do we process this data?
The processing serves to protect our users against unwanted and fraudulent calls. We rely on legitimate interests pursuant to Art. 6(1)(f) GDPR — our users’ interest in knowing who is calling before accepting a call, as well as our interest in providing this service.
We do not upload our users’ address books and do not use private contact data as a data source. Numbers transmitted with caller ID suppression active cannot be identified.
Who receives the data?
- Users of the Clever Dialer app (display on an incoming call or reverse lookup)
- Users of the Clever Dialer website (number search)
- Technical service providers within the scope of processing on our behalf (hosting, infrastructure), exclusively in the EU:
- Google Cloud EMEA Limited, data centre location Belgium (europe-west1-3). The Google Cloud data protection terms apply. Google LLC is certified under the EU-US Data Privacy Framework.
How long do we store the data?
Clever Dialer does not store individual call events. For phone numbers classified as spam or blocked by users, only aggregated statistical data is retained (number of spam classifications and blocks, as well as the country). This data is deleted as soon as the phone number is removed from the Clever Dialer spam database.
Your rights as a number holder. You can at any time:
- Request information on which data we have stored on your number
- Request the rectification of incorrect entries
- Request the erasure of your number from our database
- Object to the processing
Contact: privacy@cleverdialer.com
As we process millions of phone numbers and, as a rule, have no means of contact other than the phone number itself, individually notifying each data subject would involve disproportionate effort (Art. 14(5)(b) GDPR). We therefore make this information publicly available via our privacy policy.
4. App permissions and associated data processing
From Android 10 onwards, Clever Dialer uses the official Android role “Caller ID and Spam App”. The associated permissions (phone state, call log, internet) are necessary for the core function of the app; the legal basis is Section 25(2) no. 2 TDDDG in conjunction with Art. 6(1)(b) GDPR. Details on the data processed in this context can be found in the section Processing of personal data.
Access to your contacts is optional and serves to exclude saved contacts from the spam check. The legal basis is your consent (Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR). You can withdraw this at any time in the Android settings; the app continues to operate in its basic functions without this permission, but certain features are then no longer available:
- Excluding local contacts from caller identification
- Favourites display and management
- Receiving calls from contacts only
5. Automatically collected data when using the app (server log files)
When you use the Clever Dialer app, it communicates with our servers in order to provide you with the requested services (e.g. phone number identification, spam ratings, reverse lookup queries). In doing so, the following technical information is automatically collected and stored in server log files:
- IP address of the requesting device
- Date and time of the request
- Type and version of the operating system (e.g. Android version)
- Device type and identifier
- Type and scope of the data retrieved (e.g. API endpoint)
This data is technically necessary in order to ensure the app’s functionality and to enable communication between the app and the server.
In accordance with our IT security concept, the resulting log file data is stored for a period of 90 days in order to detect and analyse any attacks on our systems. The legal basis for the data processing is Art. 6(1) sentence 1(f) GDPR. Our legitimate interest lies in ensuring system security and maintaining the service.
6. Processing of data – your enquiries
If you send us an enquiry by email or via the contact form, we collect the data you provide in order to process and respond to your request. We store this information for evidentiary purposes for a period of three years. The legal basis for the data processing is Art. 6(1) sentence 1(f) GDPR.
Our email communication is received and stored via the infrastructure of our processor DomainFactory GmbH. Incoming enquiries are then recorded and processed as support tickets in our ticketing system LiveAgent, provided by Quality Unit, s.r.o. In this context, your email address, the content of your message including any attachments, and the entire communication history are stored in the ticketing system. Further information on these processors can be found in Section III.9.
7. Data processing in connection with Clever Dialer PRO
Clever Dialer offers the paid version Clever Dialer PRO, which is purchased and managed exclusively via the Google Play Store. With PRO, the display of advertisements ceases and extended features are unlocked.
PRO is available as a subscription with recurring payment or as a one-time payment (“Longlife”) with an unlimited entitlement.
Payment processing: All payment processing as well as the management of subscriptions and one-time purchases is carried out by Google Ireland Limited via the Google Play Store. We do not receive any payment data (e.g. credit card numbers, bank details) and do not store any contract or purchase data in our own systems. For the data processing by Google, we refer to Google’s privacy policy.
Verification of the entitlement: In order to be able to provide you with the PRO features, our app queries the Google Play Billing interface at regular intervals to determine whether a valid entitlement exists. In the case of a subscription, it is checked whether this is active; in the case of a one-time payment (“Longlife”), whether the corresponding purchase exists. In each case, only the entitlement status (entitled/not entitled) is retrieved. This information is not stored permanently in our systems; the status is only held temporarily on the device until the next check takes place.
Legal basis: Art. 6(1)(b) GDPR (performance of the purchase contract for Clever Dialer PRO — provision of the purchased features).
Effects on other data processing: Where a PRO entitlement exists, the display of advertisements ceases. The data processing for advertising purposes by advertising networks described in Section IV.4 does not take place in the PRO version.
8. Notes on ensuring data security
We protect your data in particular through the following measures:
- Encrypted transmission of all data between the app and our servers as well as between our servers and third-party providers (TLS encryption)
- Encrypted storage of data on the storage media of our data centre operator (Google Cloud Platform)
- Deletion of statistical phone number data when the number is removed from the spam database
- Automatic deletion of log data after 90 days
Security of data transmission
Communication between the Clever Dialer app and our servers takes place exclusively via a TLS-encrypted connection. In addition, we use certificate pinning to ensure that the app communicates exclusively with our verified servers. We furthermore employ technical and organisational measures pursuant to Art. 32 GDPR in order to protect your personal data against loss, destruction, manipulation and unauthorised access. Our security measures are reviewed regularly and adapted to the state of the art.
We point out that, despite these measures, a residual risk remains with any data transmission over the internet and that complete protection cannot be fully guaranteed.
We additionally recommend that you protect your device through regular software updates, an active screen lock and the use of trustworthy networks.
9. Use of processors
To provide our services, we use external service providers that process personal data on our behalf. These service providers are processors within the meaning of Art. 28 GDPR. We have concluded data processing agreements with all processors that meet the requirements of Art. 28 GDPR. The processors process personal data exclusively on our instructions and are contractually obliged to comply with appropriate technical and organisational measures to protect the data.
9.1 Web service – Google Cloud Services
For hosting the Clever Dialer web service, we use the Google Cloud Platform of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, as a processor. The web service is the central technical infrastructure of the app: for every incoming and outgoing call, the app transmits the caller’s phone number to this web service, which carries out the comparison with directory databases and the Clever Dialer spam database and returns the result to the app. Reverse lookups, ratings and spam reports are also processed via the web service. In this context, in particular the data described in Sections III.1 and III.4 is processed, including phone numbers, aggregated statistical data on spam classifications and blocks, ratings, IP addresses and technical device information. The data processing takes place exclusively in the Google Cloud region europe-west1 (Brussels, Belgium).
Customer data is thus stored and processed within the European Union. Google LLC has its headquarters in the USA; access to personal data from the USA cannot be ruled out in the course of support and maintenance activities. For this case, we base the transfer on the European Commission’s adequacy decision of 10 July 2023 on the EU-U.S. Data Privacy Framework pursuant to Art. 45(1) GDPR; Google LLC is certified under the Data Privacy Framework (cf. https://www.dataprivacyframework.gov/list).
In addition, the standard contractual clauses approved by the European Commission pursuant to Art. 46(2)(c) GDPR are part of the data processing agreement (Google Cloud Data Processing Addendum). Google uses sub-processors to provide the cloud services; their current list can be viewed at https://cloud.google.com/terms/subprocessors. Google implements extensive technical and organisational security measures, which are documented in Annex 2 of the data processing agreement and include, among other things, physical data centre security, network security, access control, data encryption in transit and at rest, intrusion detection, and regular security audits (ISO 27001, ISO 27017, ISO 27018, SOC 2/3). The Google Cloud Platform holds a PCI-DSS compliance certification. The substantive legal bases for the data processed via the web service arise from the sections in which the respective processing is described, in particular from Sections III.1–4 for caller identification and spam protection as well as from Section III.5 for the server log files.
9.2 Mail hosting – Domain Factory
For hosting our business email communication, we use DomainFactory GmbH, c/o WeWork, Neuturmstrasse 5, 80331 Munich, Germany, as a processor. DomainFactory provides the email infrastructure through which all incoming and outgoing email messages are received, stored and sent. This includes in particular the receipt of support enquiries to support@cleverdialer.de and privacy@cleverdialer.com as well as communication in connection with the exercise of data subject rights. In this context, the email addresses of senders and recipients, the contents and attachments of the email messages, as well as metadata of the communication such as timestamps, IP addresses and header information are processed.
The processing takes place in data centres in the European Union, specifically in Cologne (Germany) and Strasbourg (France). DomainFactory uses sub-processors to provide the service, some of which may be located in third countries outside the EEA, in particular in the USA. Insofar as personal data is transferred to third countries in this context, this is done on the basis of standard contractual clauses pursuant to Art. 46(2)(c) GDPR and/or on the basis of the European Commission’s adequacy decision on the EU-U.S. Data Privacy Framework pursuant to Art. 45(1) GDPR, insofar as the respective sub-processor is certified thereunder. The substantive legal bases for the communication handled via DomainFactory arise from the sections in which the relevant processing is described, in particular from Section III.6 for support enquiries as well as from Section II for the exercise of data subject rights.
9.3 Ticketing system – LiveAgent
For the management and processing of incoming enquiries, we use the ticketing system LiveAgent, provided by Quality Unit, s.r.o., Vajnorská 100/A, 831 04 Bratislava, Slovakia, as a processor. Incoming email enquiries — in particular support enquiries and requests to exercise data subject rights — are recorded as tickets in the LiveAgent system and managed, tracked and answered there in a structured manner. In this context, the name of the enquirer, insofar as it is provided, the email address, the content and any attachments of the enquiry, the entire communication history in the form of the ticket history, the IP address of the enquirer, as well as timestamps of the enquiry and of its processing are processed.
In addition, further personal data that the enquirer provides in the course of their communication may be processed. This concerns in particular users of the app who contact us by email, number holders who exercise their data subject rights, and other persons who get in touch with us. Quality Unit, s.r.o. has its registered office in the European Union. Insofar as sub-processors are used, these are listed at www.ladesk.com/gdpr. Insofar as a transfer of personal data to countries outside the EEA takes place in this context, this is done on the basis of appropriate safeguards pursuant to Art. 46 GDPR, in particular standard contractual clauses, or on the basis of an adequacy decision pursuant to Art. 45 GDPR. Tickets and the personal data contained therein are stored for the duration of processing and subsequently for a period of three years for evidentiary purposes. After this retention period expires, the data is deleted.
The substantive legal bases for the data processed in the ticketing system arise from the sections in which the relevant communication is described, in particular from Section III.6 for enquiries as well as from Section II for the exercise of data subject rights.
Information on further processors used in connection with individual functions or services of the app can be found in the respective sections of this privacy policy. This concerns in particular Google LLC for Google Analytics for Firebase and Firebase Crashlytics (Sections IV.1 and IV.2), the advertising networks named in Section IV.4, as well as OneTrust Technology Limited as the consent management platform (Section V.1).
IV. Tracking
1. Tracking through Google Analytics for Firebase
This app uses Google Analytics for Firebase, a web analytics service of Google LLC (“Google”). Google Analytics for Firebase is able, via a so-called Software Development Kit (SDK), to enable an analysis of the use of the app. The information generated about your use of this app is generally transmitted to a Google server in the USA and stored there. On our behalf, Google will use this information to evaluate your use of the app, to compile reports on app activities, and to provide us with further services associated with app usage. We have concluded a data processing agreement with Google pursuant to Art. 28 GDPR.
The legal basis for the use of Google Analytics for Firebase and the associated access to information on your device (in particular the app instance ID, device identifiers) is your consent pursuant to Art. 6(1) sentence 1(a) GDPR in conjunction with Section 25(1) TDDDG. Consent is obtained via our consent dialog before data is first collected. You can withdraw your consent at any time with effect for the future by making the corresponding change in the app settings under “Privacy Settings”. The data collected by Google Analytics for Firebase is automatically deleted after 26 months.
We use Google Analytics for Firebase in order to be able to analyse and regularly improve the use of our app. Through the statistics obtained, we can improve our offering and make it more interesting for you as a user.
Transfer of data to third countries: Insofar as personal data is transferred to the USA, this is done on the basis of the European Commission’s adequacy decision of 10 July 2023 pursuant to Art. 45(1) GDPR (EU-U.S. Data Privacy Framework). Google LLC is certified under the EU-U.S. Data Privacy Framework (cf. https://www.dataprivacyframework.gov/list). In addition, we base the transfer on the standard contractual clauses issued by the European Commission pursuant to Art. 46(2)(c) GDPR, which Google offers as part of the Data Processing Addendum. Further information can be found at https://policies.google.com/privacy and https://business.safety.google/adprocessorterms/.
2. Transfer of data for error analysis (Firebase Crashlytics)
This app uses Firebase Crashlytics, an error analysis tool of Google LLC (“Google”). Via an SDK, Crashlytics is able to transmit data on errors occurring in the app (e.g. crashes) to Crashlytics. The information generated about the error behaviour of this app is generally transmitted to a Google server in the USA and stored there. Transmitted in this context are state information of the app and the device, operating system information, hardware information, and a rough localisation based on the IP address. In addition, an ID is transmitted that identifies the device and is regenerated with each installation. We have concluded a data processing agreement with Google pursuant to Art. 28 GDPR.
The legal basis for the use of Firebase Crashlytics and the associated access to information on your device is your consent pursuant to Art. 6(1) sentence 1(a) GDPR in conjunction with Section 25(1) TDDDG. Consent is obtained via our consent dialog before data is first collected. You can withdraw your consent at any time with effect for the future by making the corresponding change in the app settings under “Privacy Settings”. The data collected by Firebase Crashlytics is automatically deleted after 90 days.
We use Crashlytics in order to be able to analyse the error behaviour of our app and to fix occurring errors more quickly. Through the insights gained, we can improve our app and achieve a more pleasant user experience for you as a user.
Transfer of data to third countries: Insofar as personal data is transferred to the USA, this is done on the basis of the European Commission’s adequacy decision of 10 July 2023 pursuant to Art. 45(1) GDPR (EU-U.S. Data Privacy Framework). Google LLC is certified under the EU-U.S. Data Privacy Framework (cf. https://www.dataprivacyframework.gov/list). In addition, we base the transfer on the standard contractual clauses pursuant to Art. 46(2)(c) GDPR. Further information can be found at https://policies.google.com/privacy, https://business.safety.google/adprocessorterms/ and https://firebase.google.com/terms/crashlytics-app-distribution-data-processing-terms.
3. Use by minors
Clever Dialer is aimed at adults and young people aged 16 and over. The app is not intended for children under 16. We do not knowingly collect personal data from children under 16. Should we become aware that a child under 16 has transmitted personal data to us, we will delete it without undue delay. Parents or legal guardians who suspect that their child has transmitted personal data to us can contact us at privacy@cleverdialer.com.
4. Use of advertising SDKs and advertising networks
In the free version of this app, advertisements are displayed. For this purpose, we use Software Development Kits (SDKs) from advertising partners that read out and store information on your device (in particular your Google Advertising ID, device information and usage data). This information is transmitted to the respective advertising networks in order to deliver interest-based advertising, control the ad frequency, and measure the effectiveness of advertising campaigns.
The legal basis for the access to information on your device by advertising SDKs is your consent pursuant to Art. 6(1) sentence 1(a) GDPR in conjunction with Section 25(1) TDDDG. Consent is obtained via our consent dialog before data is first collected. You can withdraw your consent at any time with effect for the future via the “Privacy Settings” in the app.
Specifically, we use the following advertising SDKs and advertising networks:
4.1 Unity Ads (Unity LevelPlay)
Advertising and ad mediation: In the free version of our app, advertising is displayed. For the delivery and mediation of advertising, we use the Unity LevelPlay service of Unity Technologies S.F., 116 New Montgomery Street, Suite 200, San Francisco, CA 94105, USA (“Unity”).
Unity LevelPlay acts as an ad mediator and can forward ad requests to various advertising networks. In this context, personal data is transmitted to Unity as well as to the advertising networks named below. Each advertising network is an independent controller within the meaning of Art. 4 no. 7 GDPR for the data processing it carries out.
Data processed: The advertising identifier of the device (e.g. Google Advertising ID), IP address, device information (model, operating system, screen size), app identifier, timestamp, as well as interaction data with displayed advertising (e.g. clicks, display duration).
Legal basis: Consent (Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG).
Right to object: Independently of consent, you can also restrict the use of your advertising ID for personalised advertising at device level. You will find the corresponding setting in your device’s Android settings under the Google advertising settings; there you can turn off ad personalisation or delete your advertising ID. The exact name and location of the setting may vary depending on the Android version and the device manufacturer.
Transfer of data to third countries: USA — on the basis of the standard contractual clauses (SCCs) pursuant to Art. 46(2)(c) GDPR (cf. https://unity.com/legal/unity-data-processing-addendum-dpa) as well as, where applicable, the adequacy decision on the EU-U.S. Data Privacy Framework, insofar as Unity is certified thereunder.
Privacy policy: https://unity.com/legal/privacy-policy
4.2 Meta Audience Network
Provider: Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, D04 X2K5, Ireland; parent company: Meta Platforms, Inc., Menlo Park, California, USA
Purpose: Delivery of advertisements within the app, measurement of advertising effectiveness, personalisation of advertising
Data processed: Advertising ID, IP address, device information, app usage data, advertising interaction data
Through the integration of the Meta Audience Network SDK, personal data is transmitted to Meta Platforms Ireland Limited. For the collection and transmission of this data, we and Meta are each responsible in terms of data protection law. We are responsible for obtaining your consent and for providing this data protection information. Meta processes the transmitted data as an independent controller for its own purposes, in particular:
- Improvement and optimisation of Meta’s advertising services
- Aggregation with data from other publishers and advertisers
- Personalisation of content within the Meta ecosystem
Legal basis: Consent (Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG).
Transfer of data to third countries: USA — on the basis of the European Commission’s adequacy decision on the EU-U.S. Data Privacy Framework (Meta Platforms, Inc. is DPF-certified) as well as additionally on the basis of the standard contractual clauses (SCCs) pursuant to Art. 46(2)(c) GDPR.
Objection and opt-out: You can object to the use of your data for personalised advertising at any time:
- In your Android device’s advertising settings (turning off ad personalisation)
- At Your Online Choices (EU)
- At Digital Advertising Alliance
If you withdraw your consent, no further advertisements will be delivered via the Meta Audience Network. The lawfulness of the processing carried out up to the point of withdrawal remains unaffected.
Further information on data processing by Meta can be found in the Meta privacy policy. Meta Platforms Ireland Limited, as an independent controller, can be reached via the Meta Privacy Center.
4.3 Vungle / Liftoff
Provider: Liftoff Mobile, Inc., Redwood City, California, USA
Purpose: Delivery of advertisements within the app, measurement of advertising effectiveness
Data processed: Advertising ID, IP address, device information, app usage data, advertising interaction data, rough location data (based on the IP address)
Legal basis: Consent (Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG)
Transfer of data to third countries: USA — on the basis of the standard contractual clauses (SCCs) pursuant to Art. 46(2)(c) GDPR as well as, where applicable, the adequacy decision on the EU-U.S. Data Privacy Framework, insofar as Liftoff Mobile, Inc. is certified thereunder (cf. https://www.dataprivacyframework.gov/list).
Privacy policy: https://liftoff.io/privacy-policy/
4.4 InMobi
Provider: InMobi Pte. Ltd., 30 Cecil Street, #21-08 Prudential Tower, Singapore 049712
Purpose: Delivery of advertisements within the app, measurement of advertising effectiveness
Data processed: Advertising ID, IP address, device information, app usage data, advertising interaction data, rough location data (based on the IP address).
Legal basis: Consent (Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG)
Transfer of data to third countries: Singapore and India — on the basis of the standard contractual clauses (SCCs) pursuant to Art. 46(2)(c) GDPR. For Singapore and India, there is currently no adequacy decision by the European Commission. InMobi has committed, within the scope of its Data Processing Addendum, to comply with the standard contractual clauses. In addition, technical and organisational measures (in particular encryption of the data in transit and at rest, as well as pseudonymisation through the use of advertising IDs instead of clear names) have been implemented as additional safeguards.
Privacy policy: https://www.inmobi.com/privacy-policy
V. Consent management
1. Consent management platform
To manage your data protection consents, we use the consent management platform (CMP) of the following provider:
OneTrust Technology Limited
82 St John Street, London, EC1M 4JN, United Kingdom
Privacy policy: https://www.onetrust.com/privacy-notice/
Sellwerk GmbH & Co. KG participates in the IAB Europe Transparency & Consent Framework and complies with its Specifications and Policies. Sellwerk GmbH & Co. KG uses the Consent Management Platform with the identification number 28.
When using OneTrust, the following data is processed:
- Your consent decisions (consent string / TC string)
- Device/app identifier for assigning the consent
- Time at which consent was given or changed
- Language setting and app version
The legal basis for the use of OneTrust is Art. 6(1)(c) GDPR (fulfilment of our legal obligations to demonstrate consent pursuant to Art. 7(1) GDPR) as well as Section 25(2) no. 2 TDDDG (technically necessary access). The consent data stored server-side at OneTrust is stored for the duration of our contractual relationship with OneTrust and deleted upon its termination.
OneTrust processes data as our processor on the basis of a data processing agreement pursuant to Art. 28 GDPR (OneTrust Data Processing Addendum). Insofar as a transfer to the United Kingdom takes place in this context, this is done on the basis of the European Commission’s adequacy decision (Art. 45 GDPR).
OneTrust LLC has certified its participation in the EU-US Data Privacy Framework (DPF). The transfer of personal data to the USA is therefore based primarily on the European Commission’s adequacy decision pursuant to Art. 45 GDPR in conjunction with Implementing Decision (EU) 2023/1795.
In addition, the standard contractual clauses (SCCs) approved by the European Commission pursuant to Art. 46(2)(c) GDPR are part of the data processing agreement. These serve as an additional safeguard and fallback in the event that the DPF should cease to apply. OneTrust has also implemented supplementary technical and organisational measures within the meaning of the EDPB Recommendations 01/2020.
Further information on OneTrust’s security measures as well as the current list of sub-processors used by OneTrust can be found at: https://my.onetrust.com/s/list-of-subprocessors
2. Consent dialog and consent options
When the app is first started, you are shown a consent dialog in which you are informed in a granular manner about the intended data processing operations. You have the following choices:
- (a) Accept all processing
- (b) Reject all rejectable processing
- (c) Individual selection by processing purpose and/or individual advertising partners (vendors)
You can change or withdraw your consents at any time thereafter under:
Settings → Privacy Settings
The withdrawal of consent does not affect the lawfulness of the processing carried out up to the point of withdrawal (Art. 7(3) GDPR).
3. Processing purposes under IAB TCF 2.3
Within the scope of TCF 2.3, the following standardised processing purposes are disclosed in our app. The names and descriptions are prescribed by IAB Europe and are identical to those shown to you in the consent dialog.
Purposes for which we obtain your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG)
- Purpose 1: Store and/or access information on a device
- Purpose 2: Use limited data to select advertising
- Purpose 3: Create profiles for personalised advertising
- Purpose 4: Use profiles to select personalised advertising
- Purpose 5: Create profiles to personalise content
- Purpose 6: Use profiles to select personalised content
- Purpose 7: Measure advertising performance
- Purpose 8: Measure content performance
- Purpose 9: Understand audiences through statistics or combinations of data from different sources
- Purpose 10: Develop and improve services
- Purpose 11: Use limited data to select content
Purposes that individual advertising partners base on a legitimate interest as an alternative (Art. 6(1)(f) GDPR)
For purposes 2, 7, 8, 9, 10 and 11, the framework permits a legitimate interest as a legal basis in addition to consent (Art. 6(1)(f) GDPR). Which of the two bases an advertising partner relies on for which purpose is determined by the respective partner; you will find this information for each individual partner in the “Privacy Settings”. Insofar as a partner relies on a legitimate interest, you can object there at any time (Art. 21 GDPR). For purposes 1, 3, 4, 5 and 6, only your consent is permissible.
Special purposes (Art. 6(1)(f) GDPR)
Special purposes serve the technically sound and secure operation of the service. The framework does not provide for a right to object in respect of them.
- Special purpose 1: Ensure security, prevent and detect fraud, and fix errors
- Special purpose 2: Deliver and present advertising and content
- Special purpose 3: Save and communicate privacy choices
Features
Features are means of processing that are used solely to fulfil the purposes named above. They do not require separate consent, as they are covered by the decision on the respective purpose.
- Feature 1: Match and combine data from other data sources
- Feature 2: Link different devices
- Feature 3: Identify devices based on information transmitted automatically
Special features
Special features are only used if you expressly consent to them in the consent dialog. Without your consent, the corresponding processing does not take place.
- Special feature 2: Identify devices based on information actively requested
4. Advertising partners (vendors)
In the free, ad-financed version of the app, we work with advertising partners that are registered as vendors in the IAB TCF.
You can view the complete and current list of the advertising partners we use at any time in the app’s consent dialog:
Settings → Privacy Settings
Each advertising partner is listed there with the following information:
- Name and privacy policy of the advertising partner
- Processing purposes used and the respective legal basis (consent or legitimate interest)
- Storage duration of the information stored on your device
There you can grant or refuse consent to each individual advertising partner, or object to its legitimate interest.
As of: August 2026